Description
Webmin 0.92, when installed from an RPM, creates /var/webmin with insecure permissions (world readable), which could allow local users to read the root user's cookie-based authentication credentials and possibly hijack the root user's session using the credentials.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2002-1653 | Webmin 0.92, when installed from an RPM, creates /var/webmin with insecure permissions (world readable), which could allow local users to read the root user's cookie-based authentication credentials and possibly hijack the root user's session using the credentials. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-08T03:34:55.701Z
Reserved: 2005-06-21T00:00:00.000Z
Link: CVE-2002-1672
No data.
Status : Modified
Published: 2002-12-31T05:00:00.000
Modified: 2026-04-16T00:27:16.627
Link: CVE-2002-1672
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD